First published: Wed Dec 18 2019(Updated: )
Insufficient Input validation in the subsystem for Intel(R) CSME before versions 12.0.45,13.0.10 and 14.0.10 may allow a privileged user to potentially enable denial of service via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Converged Security Management Engine Firmware | >=12.0<12.0.45 | |
Intel Converged Security Management Engine Firmware | >=13.0<13.0.10 | |
Intel Converged Security Management Engine Firmware | >=14.0.0<14.0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2019-0165.
The title of this vulnerability is "Insufficient Input validation in the subsystem for Intel(R) CSME before versions 12.0.45, 13.0.10, and 14.0.10."
The severity value of CVE-2019-0165 is 4.4 (Medium).
The Intel Converged Security Management Engine Firmware versions 12.0 (up to 12.0.45), 13.0 (up to 13.0.10), and 14.0 (up to 14.0.10) are affected.
A privileged user may be able to enable denial of service via local access.